aperture
Aperture enables payment-gated API access via the Lightning Network, facilitating secure transactions for backend services.
Install this skill
Security score
The aperture skill was audited on May 22, 2026 and we found 22 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Access to hidden dotfiles in home directory
| 26 | --save-to ~/.lnd/data/chain/bitcoin/mainnet/invoice.macaroon |
Access to hidden dotfiles in home directory
| 75 | This generates `~/.aperture/aperture.yaml` from the config template with |
Access to hidden dotfiles in home directory
| 86 | --lnd-tls ~/.lnd/tls.cert \ |
Access to hidden dotfiles in home directory
| 87 | --lnd-macdir ~/.lnd/data/chain/bitcoin/mainnet |
Access to hidden dotfiles in home directory
| 107 | Starts aperture as a background process reading `~/.aperture/aperture.yaml`. |
Access to hidden dotfiles in home directory
| 124 | Config file: `~/.aperture/aperture.yaml` |
Access to hidden dotfiles in home directory
| 137 | --save-to ~/.lnd/data/chain/bitcoin/mainnet/invoice.macaroon |
Access to hidden dotfiles in home directory
| 154 | dbfile: "~/.aperture/aperture.db" |
Access to hidden dotfiles in home directory
| 159 | tlspath: "~/.lnd/tls.cert" |
Access to hidden dotfiles in home directory
| 160 | macdir: "~/.lnd/data/chain/bitcoin/mainnet" |
Access to hidden dotfiles in home directory
| 220 | tlspath: "~/.lnd/tls.cert" |
Access to hidden dotfiles in home directory
| 221 | macdir: "~/.lnd/data/chain/bitcoin/mainnet" |
Access to hidden dotfiles in home directory
| 247 | dbfile: "~/.aperture/aperture.db" |
Access to hidden dotfiles in home directory
| 273 | If neither is set, Aperture generates self-signed certs in `~/.aperture/`. |
Access to hidden dotfiles in home directory
| 331 | | `~/.aperture/aperture.yaml` | Configuration file | |
Access to hidden dotfiles in home directory
| 332 | | `~/.aperture/aperture.db` | SQLite database | |
Access to hidden dotfiles in home directory
| 333 | | `~/.aperture/tls.cert` | TLS certificate | |
Access to hidden dotfiles in home directory
| 334 | | `~/.aperture/tls.key` | TLS private key | |
Access to hidden dotfiles in home directory
| 335 | | `~/.aperture/aperture.log` | Log file | |
External URL reference
| 32 | lnget -k --no-pay https://localhost:8081/api/test |
External URL reference
| 306 | lnget --max-cost 100 https://localhost:8081/api/info.json |
External URL reference
| 321 | lnget --max-cost 1000 https://localhost:8081/api/data |